CVE-2020-15897: Arista Eos

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Arista EOS before 4.21.12M, 4.22.x before 4.22.7M, 4.23.x before 4.23.5M, and 4.24.x before 4.24.2F allows remote attackers to cause traffic loss or incorrect forwarding of traffic via a malformed link-state PDU to the IS-IS router.

Affected products

  • Arista Eos: before 4.21.12m (fixed in 4.21.12m); from 4.22, before 4.22.7m (fixed in 4.22.7m); from 4.23, before 4.23.5m (fixed in 4.23.5m); from 4.24, before 4.24.2f (fixed in 4.24.2f)

Published 2020-10-26. Last modified 2026-06-17.